Aggregator
CVE-2025-3801 | songquanpeng one-api up to 0.6.10 System Setting Homepage Content cross site scripting
9 months 3 weeks ago
A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System Setting Handler. The manipulation of the argument Homepage Content leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-3801. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #554779: thautwarm vscode-diana 0.0.1 Improper Neutralization of Special Elements Used in a Template E [Accepted]
9 months 3 weeks ago
Submit #554779 / VDB-305658
ybdesire
Submit #554756: Tenda w12,i24 w12 V3.0.0.5(3644) and i24 V3.0.0.4(2887) Stack-based Buffer Overflow [Accepted]
9 months 3 weeks ago
Submit #554756 / VDB-305657
T1an
Submit #554746: Tenda w12 and i24 w12 V3.0.0.5(3644) and i24 V3.0.0.4(2887) Stack-based Buffer Overflow [Accepted]
9 months 3 weeks ago
Submit #554746 / VDB-305656
T1an
CVE-2025-40364 | Linux Kernel up to 6.1.128/6.6.77 io_uring io_req_prep_async buffer overflow
9 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.1.128/6.6.77 and classified as critical. Affected by this issue is the function io_req_prep_async of the component io_uring. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2025-40364. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-3800 | WCMS 11 AnonymousController.php mobile_phone sql injection
9 months 3 weeks ago
A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/controllers/AnonymousController.php. The manipulation of the argument mobile_phone leads to sql injection.
This vulnerability is known as CVE-2025-3800. The attack can be launched remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.
vuldb.com
CVE-2025-3799 | WCMS 11 AnonymousController.php email/username sql injection
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app/controllers/AnonymousController.php. The manipulation of the argument email/username leads to sql injection.
This vulnerability is traded as CVE-2025-3799. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.
vuldb.com
CVE-2025-3798 | WCMS 11 Advertisement Image AdvadminController.php sub unrestricted upload
9 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminController.php of the component Advertisement Image Handler. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-3798. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CBRN-specialisten spijkeren kennis bij
9 months 3 weeks ago
Specialisten op het gebied van chemische, biologische, radiologische en nucleaire stoffen (CBRN) hebben hun kennis bijgespijkerd. 34 in beschermende kleding gehulde militairen zijn een week lang blootgesteld aan echte zenuwgassen. Dat gebeurde in de Verenigde Staten tijdens een Toxic Agent Training. Morgen zit deze er weer op.
Submit #554702: one api latest XSS [Accepted]
9 months 3 weeks ago
Submit #554702 / VDB-305655
yaowenxiao
Оруэлл нервно курит в сторонке: "Черное зеркало" вернулось с новыми кошмарами
9 months 3 weeks ago
От подписочной зависимости до игры с чувствами ИИ — все шесть серий обескураживают.
Submit #554698: WCMS 11 SQL injection vulnerability [Accepted]
9 months 3 weeks ago
Submit #554698 / VDB-305653
icefoxh
Submit #554697: WCMS 11 SQL injection vulnerabilities [Accepted]
9 months 3 weeks ago
Submit #554697 / VDB-305652
icefoxh
Submit #554696: WCMS 11 arbitrary file upload vulnerability [Accepted]
9 months 3 weeks ago
Submit #554696 / VDB-305651
icefoxh
G.O.S.S.I.P 资源推荐 2025-04-18 编译器的开发之道
9 months 3 weeks ago
逸·编译器
G.O.S.S.I.P 资源推荐 2025-04-18 编译器的开发之道
9 months 3 weeks ago
逸·编译器
CVE-2025-3797 | SeaCMS up to 13.3 admin_topic.php?action=delall e_id sql injection
9 months 3 weeks ago
A vulnerability classified as critical was found in SeaCMS up to 13.3. This vulnerability affects unknown code of the file /admin_topic.php?action=delall. The manipulation of the argument e_id leads to sql injection.
This vulnerability was named CVE-2025-3797. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #554695: WCMS 11 XSS vulnerability [Duplicate]
9 months 3 weeks ago
Submit #554695 / VDB-302030
icefoxh
CVE-2025-3796 | PHPGurukul Men Salon Management System 1.0 /admin/contact-us.php pagetitle/pagedes/email/mobnumber/timing sql injection
9 months 3 weeks ago
A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/contact-us.php. The manipulation of the argument pagetitle/pagedes/email/mobnumber/timing leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-3796. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com